Pravda.Ua
Cl0p Ransomware Group Claims Data Theft from Shell, Philips, and Others
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Cl0p ransomware group has claimed responsibility for a significant data breach affecting nearly 50 companies, including Shell, Philips, General Electric, and Fiserv. The hackers allege to have stolen 89GB of data from Shell and 13.5GB from Philips, including sensitive engineering documents and project plans. The attacks exploit a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM software, allowing for unauthenticated remote code execution. Both Shell and Philips have confirmed attempts to breach their systems and are currently investigating the incidents. The Ransomware Information Sharing and Analysis Center (Ransom-ISAC) has issued warnings about the ongoing exploitation of these vulnerabilities. The attackers utilize a double extortion strategy, threatening to release stolen data if their demands are not met. As of now, no samples of the stolen data have been released by Cl0p.
Key Points: • Cl0p claims to have stolen 89GB from Shell and 13.5GB from Philips. • The attacks exploit a critical vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569). • Both Shell and Philips are investigating the breaches, which may affect nearly 50 companies.